Logo
TOPICS
TOPICS

AIR

SEA

LAND

SPACE

CYBER

INDUSTRY
EVENTS
EVENTS

C4ISR & BEYOND

SHIPTECH FORUM

SIMULATION & TRAINING FORUM

DEEPBLUE FORUM

MAGAZINE
PODCAST
Search
SUBSCRIBE
paper-plane-tilt
Logo
  • Home
  • Posts
  • Op-Ed: The Challenge of Regulating Critical Cyber Systems

Op-Ed: The Challenge of Regulating Critical Cyber Systems

As Canada develops regulations under the Critical Cyber Systems Protection Act, the challenge will be building a framework that balances flexibility, technical expertise and real-world security outcomes.

Allan McDougall
Allan McDougall

Aug 10, 2026

Adobe stock

As Canada's Critical Cyber Systems Protection Act moves into implementation, attention turns to the regulations that will determine how it is applied in practice. Canada now finds itself at an important crossroads. Will the regulations emphasize the development of effective security programs that can adapt their technical controls over time? Will they focus on compliance with prescribed standards? Or will they ultimately land somewhere between the two?

This is not the first time these questions have emerged. Performance-based regulation has long been discussed in sectors such as transportation. While attractive in principle, these approaches can quickly devolve into compliance regimes centred on managing plans rather than achieving outcomes. More traditional compliance models, meanwhile, are well established within the governance, risk and compliance community. Over time, however, they often become exercises in obtaining the certification required to operate rather than building genuine security capability.

With the legislation now in place, the drafting of regulations is where the real work begins. Those regulations will shape how a significant portion of Canada's critical infrastructure approaches cyber security, including third-party and supply chain risk. Before we sharpen the pencils too quickly, three challenges deserve careful consideration.

Build flexibility into the framework

The first challenge is accommodating the scope, scale and speed of technological change.

Regulations evolve deliberately. The processes that govern their development are intended to prevent unintended consequences, avoid unnecessary burdens and close potential gaps. While that pace can seem slow in many areas of public policy, the difference between regulatory change and the rate at which information technology evolves can seem nothing short of astronomical.

The implication is clear: regulations must provide sufficient flexibility to remain relevant as technology continues to evolve.

Develop technical capability, not just compliance expertise

The second challenge is addressing the education, skills and training gaps that will inevitably emerge.

Canada likely has a solid base of professionals capable of reviewing programs from a documentation and governance perspective. The greater challenge lies in developing the technical expertise needed to operate, assess and secure increasingly complex systems.

Cyber security education must extend beyond explaining frameworks and demonstrating compliance with standards. It must prepare practitioners to sit in front of an administrator's console, understand how systems actually operate, identify emerging risks and respond without creating the very disruptions they are attempting to prevent.

Building that capability will be every bit as important as building the regulatory framework itself.

Reflect the realities of modern infrastructure

The third challenge is recognizing the realities of today's interconnected systems.

Organizations increasingly depend on external infrastructure, cloud services and global technology providers. Regulations must account for that reality.

What happens when a company operating outside Canada provides critical services within Canada but declines to participate in Canada's regulatory regime? Addressing these situations requires more than rigid compliance requirements. It demands regulations that recognize there may be multiple approaches to managing security risk while still achieving acceptable outcomes.

That flexibility will require both practical experience and sound judgment throughout the regulatory development process.

From legislation to implementation

This is the time to engage industry, encourage meaningful consultation and begin establishing a trusted advisory community willing to contribute beyond immediate commercial interests.

The Critical Cyber Systems Protection Act represents an important step forward. The work ahead will determine whether Canada's regulatory framework strengthens cyber security or simply expands compliance obligations. As regulations take shape, there is an opportunity to pursue approaches that balance security, innovation and operational reality while accommodating the diverse viewpoints that inevitably accompany meaningful regulatory reform.


Filed under:

Opinion

Cyber

Stay ahead.

Defence industry stories and analysis exclusively for subscribers through email.

KEEP READING

View more
caret-right

UPCOMING EVENTS

Deep Blue Forum 2026

Deep Blue Forum 2026

October 27, 2026

Canada's forum for the technologies, capabilities and partnerships shaping the future of the underwater domain.


C4ISR and Beyond 2027

C4ISR and Beyond 2027

January 26, 2027

Canada's forum for the people, technologies and partnerships shaping command, control, communications, intelligence, surveillance and reconnaissance.

LATEST STORIES

Canadian Armed Forces launch Operation NANOOK‐TUUGAALIK in Canada’s Arctic

Canadian Armed Forces launch Operation NANOOK‐TUUGAALIK in Canada’s Arctic

Aug 14, 2026

Sea

Activities will include patrols, surveillance, community engagement, and refuelling.

Closing the Gap: Inside the Strix-DIGITAL Alliance

Closing the Gap: Inside the Strix-DIGITAL Alliance

Aug 14, 2026

Industry

Two Canadian innovation organizations just decided that solving Canada's toughest defence problems means picking up the phone and calling each other more often.

Femtum lands $1.95M CED boost for quantum photonics manufacturing

Femtum lands $1.95M CED boost for quantum photonics manufacturing

Aug 14, 2026

Cyber

Femtum builds laser solutions for manufacturers of photonic chips, with a focus on quantum photonic chips.

Canada Cannot Claim What It Cannot Sustain

Canada Cannot Claim What It Cannot Sustain

Aug 12, 2026

Land

Canada's Arctic problem is not a lack of intent—it is a lack of lift.

Detect First, Decide First, Act First

Detect First, Decide First, Act First

Aug 12, 2026

Air

Major-General Jeff Smyth, MSM, CD, Chief Air and Space Force Development, Royal Canadian Air Force, on what Canada's investment in continental defence means for the RCAF and what industry needs to understand about the road ahead.

Different Problems, Different Tools: Canada’s AEW&C Bet in a Space Age

Different Problems, Different Tools: Canada’s AEW&C Bet in a Space Age

Aug 12, 2026

Space

+1

Briefing and connecting Canada’s defence community

TOPICS

Air
Land
Naval
Space
Cyber
Industry

Explore

Magazine
Podcast
Advertise
About Us

Stay ahead.

Subscribe for you to get the briefing.


Copyright 2026 Vanguard Defence. | Privacy Policy | Contact